2023 Latest 100% Exam Passing Ratio - CAU201 Dumps PDF [Q56-Q81]

Share

2023 Latest 100% Exam Passing Ratio - CAU201 Dumps PDF

Pass Exam With Full Sureness - CAU201 Dumps with 179 Questions


CyberArk Defender certification is an intermediate-level exam, and it covers a range of topics, including the CyberArk Privileged Access Security Solution, fundamental security concepts and principles, and the deployment and configuration of CyberArk components. CAU201 exam is intended to assess the candidate's knowledge, skills, and abilities in designing, implementing, and maintaining secure privilege access environments using CyberArk. Successful completion of the exam demonstrates that the candidate has a solid understanding of the CyberArk technology and can effectively manage and secure privileged access within an organization.


To prepare for the CyberArk Defender certification exam, candidates can take advantage of various training and resources provided by CyberArk. This includes online training courses, self-paced study materials, and hands-on labs. The CyberArk training program is designed to equip candidates with the knowledge and skills needed to pass the exam and become a certified CyberArk Defender.

 

NEW QUESTION # 56
In your organization the "click to connect" button is not active by default.
How can this feature be activated?

  • A. Policies > Master Policy > Session Management > Require privileged session monitoring and isolation > Add Exception
  • B. Policies > Master Policy > Allow EPV transparent connections > Inactive
  • C. Policies > Master Policy > Password Management
  • D. Policies > Master Policy > Allow EPV transparent connections > Active

Answer: D


NEW QUESTION # 57
Which of the following files must be created or configured in order to run Password Upload Utility? Select all that apply.

  • A. PACli.ini
  • B. A comma delimited upload file
  • C. Vault.ini
  • D. conf.ini

Answer: D

Explanation:
Explanation/Reference: https://www.reddit.com/r/CyberARk/comments/84gfsb/password_upload_utility_error/


NEW QUESTION # 58
In PVWA, you are attempting to play a recording made of a session by user jsmith, but there is no option to "Fast Forward" within the video. It plays and only allows you to skip between commands instead. You are also unable to download the video.
What could be the cause?

  • A. You need to update the recorder settings in the platform to enable screen capture every 10000 ms or less.
  • B. The browser you are using is out of date and needs an update to be supported.
  • C. Recording is of a PSM for SSH session.
  • D. You do not have the "View Audit" permission on the safe where the account is stored.

Answer: B


NEW QUESTION # 59
In a default CyberArk installation, which group must a user be a member of to view the "reports" page in PVWA?

  • A. PVWAReports
  • B. ReportUsers
  • C. Operators
  • D. PVWAMonitor

Answer: D


NEW QUESTION # 60
Arrange the steps to restore a Vault using PARestore for a Backup in the correct sequence.

Answer:

Explanation:


NEW QUESTION # 61
When a group is granted the 'Authorize Account Requests' permission on a safe Dual Control requests must be approved by

  • A. The number of persons specified by the Master Policy
  • B. Every person from that group
  • C. Any one person from that group
  • D. That access cannot be granted to groups

Answer: A


NEW QUESTION # 62
When Dual Control is enabled a user must first submit a request in the Password Vault Web Access (PVWA) and receive approval before being able to launch a secure connection via PSM for Windows (previously known as RDP Proxy).

  • A. False, a user can submit the request after the connection has already been initiated via the PSM for Windows
  • B. True

Answer: A


NEW QUESTION # 63
Which of the following statements are NOT true when enabling PSM recording for a target Windows server? (Choose all that apply)

  • A. PSM must be enabled in the Master Policy (either directly, or through exception)
  • B. The PSM software must be instated on the target server
  • C. PSMConnect must be added as a local user on the target server
  • D. RDP must be enabled on the target server

Answer: A,B


NEW QUESTION # 64
If a user is a member of more than one group that has authorizations on a safe, by default that user is
granted____________________.

  • A. only those permissions that exist on the group added to the safe first.
  • B. only those permissions that exist in all groups to which the user belongs.
  • C. the cumulative permissions of all the groups to which that user belongs.
  • D. the vault will not allow this situation to occur.

Answer: A


NEW QUESTION # 65
Which Master Policy Setting must be active in order to have an account checked-out by one user for a pre- determined amount of time?

  • A. Enforce one-time password access
  • B. Enforce check-in/check-out exclusive access & Enforce one-time password access
  • C. Enforce check-in/check-out exclusive access
  • D. Require dual control password access Approval

Answer: C

Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PrivCloud/Latest/en/Content/Privilege%
20Cloud/privCloud-master-policy-rules.htm


NEW QUESTION # 66
Which keys are required to be present in order to start the PrivateArk Server service?

  • A. Server key
  • B. Recovery private key
  • C. Recovery public key
  • D. Safe key

Answer: A,C


NEW QUESTION # 67
When managing SSH keys, the CPM stored the Private Key

  • A. In the Vault
  • B. A & B
  • C. On the target server
  • D. Nowhere because the private key can always be generated from the public key.

Answer: A

Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/SSHKM/Managing%
20SSH%20Keys.htm


NEW QUESTION # 68
When on-boarding account using Accounts Feed, which of the following is true?

  • A. Any account that is on-boarded can be automatically reconciled regardless of the platform it is associated with.
  • B. You must specify an existing Safe where the account will be stored when it is on-boarded to the Vault.
  • C. You can specify the name of a new safe that will be created where the account will be stored when it is on- boarded to the Vault.
  • D. You can specify the name of a new Platform that will be created and associated with the account.

Answer: D

Explanation:
Explanation/Reference: https://www.cyberark.com/resource/automating-privileged-account-onboarding/


NEW QUESTION # 69
Which values are acceptable in the address field of an Account?

  • A. It must be NetBIOS name
  • B. It must be a Fully Qualified Domain Name (FQDN)
  • C. It must be an IP address
  • D. Any name that is resolvable on the Central Policy Manager (CPM) server is acceptable

Answer: D


NEW QUESTION # 70
A user requested access to view a password secured by dual-control and is unsure who to contact to expedite the approval process. The Vault Admin has been asked to look at the account and identify who can approve their request.
What is the correct location to identify users or groups who can approve?

  • A. PVWA> Account List > Edit > Show Advanced Settings > Dual Control > Direct Managers
  • B. PVWA> Policies > Access Control (Safes) > Safe Members > Workflow > Authorize Password Requests
  • C. PVWA> Administration > Platform Configuration > Edit Platform > UI & Workflow > Dual Control> Approvers
  • D. PrivateArk > Admin Tools > Users and Groups > Auditors (Group Membership)

Answer: B


NEW QUESTION # 71
What is the configuration file used by the CPM scanner when scanning UNIX/Linux devices?

  • A. plink.exe
  • B. PVConfig.xml
  • C. dbparm.ini
  • D. UnixPrompts.ini

Answer: D


NEW QUESTION # 72
Which report provides a list of accounts stored in the vault.

  • A. Activity Log
  • B. Privileged Accounts Inventory
  • C. Entitlement Report
  • D. Privileged Accounts Compliance Status

Answer: B

Explanation:
Explanation/Reference: https://techinsight.com.vn/language/en/privileged-account-security-solution-part-2/


NEW QUESTION # 73
What is the primary purpose of One Time Passwords?

  • A. More frequent password changes
  • B. Reduced risk of credential theft
  • C. Non-repudiation (individual accountability)
  • D. To force a 'collusion to commit' fraud ensuring no single actor may use a password without authorization.

Answer: B


NEW QUESTION # 74
SAFE Authorizations may be granted to____________.
Select all that apply.

  • A. Vault Group
  • B. Vault Users
  • C. LDAP Users
  • D. LDAP Groups

Answer: A,B,C,D


NEW QUESTION # 75
Which report shows the accounts that are accessible to each user?

  • A. Entitlement report
  • B. Applications Inventory report
  • C. Privileged Accounts Compliance Status report
  • D. Activity report

Answer: A


NEW QUESTION # 76
Which of the following PTA detections are included in the Core PAS offering?

  • A. Unmanaged Privileged Access
  • B. Golden Ticket
  • C. Over-Pass-The Hash
  • D. Suspected Credential Theft

Answer: A

Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PTA/What-Does-PTA-
Detect.htm


NEW QUESTION # 77
It is possible to control the hours of the day during which a user may log into the vault.

  • A. FALSE
  • B. TRUE

Answer: B


NEW QUESTION # 78
The Password upload utility can be used to create safes.

  • A. FALSE
  • B. TRUE

Answer: A

Explanation:
Explanation/Reference:


NEW QUESTION # 79
Which permissions are needed for the Active Directory user required by the Windows Discovery process?

  • A. Read
  • B. LDAP Admin
  • C. Read/Write
  • D. Domain Admin

Answer: A


NEW QUESTION # 80
What is the purpose of a linked account?

  • A. To allow more than one account to work together as part of a password management process.
  • B. To connect the CPNI to a target system.
  • C. To ensure that a particular collection of accounts all have the same password.
  • D. To ensure a particular set of accounts all change at the same time.

Answer: A

Explanation:
Explanation/Reference: https://docs.cyberark.com/Product-Doc/OnlineHelp/PAS/Latest/en/Content/PASIMP/Linked-
Accounts.htm


NEW QUESTION # 81
......


CyberArk CAU201 certification exam is designed for individuals who are interested in pursuing a career in the field of cybersecurity. CyberArk Defender certification is offered by CyberArk, a leading provider of privileged access security solutions. The CyberArk CAU201 exam is designed to test the knowledge and skills of professionals who are responsible for administering, maintaining, and securing privileged accounts and credentials within an organization. CAU201 exam covers a wide range of topics, including CyberArk architecture, installation and configuration, password management, session management, and troubleshooting.

 

Verified CAU201 dumps Q&As - 100% Pass from DumpStillValid: https://www.dumpstillvalid.com/CAU201-prep4sure-review.html